AZ-500 Manage identity and access Practice Question
A company uses Microsoft Entra Privileged Identity Management (PIM) to manage access to Microsoft Entra ID roles. They want to require that users who activate the Global Administrator role must get approval from their manager before activation, and that the approval must be time-bound (maximum 8 hours). Which two PIM configurations should they set?
⚠ Common exam trap
Many exam-takers confuse 'justification' or 'MFA' with approval and time-bound constraints, but justification and MFA are separate security controls that do not satisfy the specific requirements for manager approval and a maximum duration.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Set the activation maximum duration to 8 hours.
Setting the activation maximum duration to 8 hours enforces the time-bound requirement, ensuring that once a user activates the Global Administrator role, the activation automatically expires after 8 hours. Option B is correct because enabling the approval workflow and adding the manager as an approver ensures that the manager must approve each activation request, meeting the requirement for manager approval. Together, these two configurations satisfy both the time-bound and approval constraints.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Set the activation maximum duration to 8 hours.
Why this is correct
Setting the activation maximum duration to 8 hours in Microsoft Entra PIM enforces a strict time-bound on any privileged role activation. This ensures that a user cannot remain in the role indefinitely; after the configured duration, the role assignment automatically expires and reverts to eligible state. Since 8 hours is the maximum allowed activation duration for Microsoft Entra ID roles, this directly satisfies the requirement that privileged access be temporary and bounded by a specific time limit.
- ✓
Enable approval workflow by adding the manager as an approver.
Why this is correct
Enabling the approval workflow and configuring the user's manager as an approver requires every activation request to be explicitly reviewed and approved by that manager before the role becomes active. This satisfies the approval requirement by adding a mandatory human control point, ensuring that privileged access is granted on-demand only after proper authorization. The approver can evaluate the request context, including the provided justification, before granting access.
- ✗
Require multi-factor authentication on activation.
Why it's wrong here
Requiring multi-factor authentication (MFA) on activation adds a strong authentication check, but it does not impose any time-bound restriction on the role nor does it introduce an approval process. In fact, Microsoft Entra PIM already enforces MFA by default for all role activations unless explicitly exempted, so configuring this alone does not address the stated requirements for time-bound and approval-based access. MFA is a valuable security control but is irrelevant to the specific compliance scenario described.
- ✗
Require justification on activation.
Why it's wrong here
Requiring a justification on activation captures an audit trail and enforces accountability, but it has no effect on how long the role remains active and does not add a separate approval step. A user could provide a justification and still receive unlimited activation duration if no maximum is configured, leaving the role permanently active. Therefore, justification only supports transparency and auditing, not the time-bound or approval requirements, so it is not the correct configurable setting for this scenario.
Go deeper
Related to this question
About these practice questions
This AZ-500 question is part of Courseiva's 617-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This AZ-500 practice question is part of Courseiva's free Microsoft certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the AZ-500 exam.